Threat Modeling? Focus on Detection!

Threat modeling means you will view your network with a subjective eye and find the most likely attack vector. from a security threat point of view.  This is similar to risk Management, where you list all devices and show which ones need the most security attention.  Threat modeling comes from a different direction – and … Read more

What Does Dark-Net Improving Mean? We Get Hacked Soon!

Wired has a story about “New Dark-Web Market Is Selling Zero-Day Exploits to Hackers” This is the new welcome greeting in the “Dark-Web or Dark-Net” essentially a webserver that is not searchable on Google, only using anonymous Browsers one can find this type of a “market” entrance. Silk Road is another venue that uses the … Read more

Must Patch Microsoft MS015-034 ASAP

Tuesday the patch was released: Here is where it started CVE-2015-1635  Description: HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka “HTTP.sys Remote Code Execution Vulnerability.” the vulnerability was created 20150217 MS:MS15-034 http://technet.microsoft.com/security/bulletin/MS15-034 … Read more

Cyber Attack Industry

Do you wonder what makes these guys who attack us every day tick?   the McAfee Article on the “growth” industry http://www.networkworld.com/article/2911167/security0/cyber-extortion-a-growth-industry.html Personally  I have bumped into a few instances of this phenomena(extortion and cryptolocker):        As well as phone extortion artists After infecting the computer they have you call them and then … Read more